IP Library Granted Patent US 12,739,631
Granted Patent B2
US 12,739,631 · App. 18/910,183 · Granted Sep 15, 2026

Secure wireless zero touch onboarding of computing devices

Inventors: Mahesh Babu Ramaiah (Bangalore, IN); Mukesh Gupta (Shrewsbury, MA); Yuvakrishnan Sadhasivam (Bengaluru, IN)
Assignee: Dell Products L.P.
H04W12/06H04W12/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,739,631
App. No.
18/910,183
Granted
Sep 15, 2026
Kind
B2
Abstract

An apparatus comprises at least one processing device configured to obtain a data structure comprising information utilizable for generating a temporary wireless credential for an endpoint computing device deployed at a first computing site, the temporary wireless credential being provisioned in the endpoint computing device at a second computing site different than the first computing site. The at least one processing device is also configured to generate the temporary wireless credential for the endpoint computing device based on the obtained data structure, to provision the temporary wireless credential in a wireless network device at the first computing site, and, responsive to successfully verifying a wireless connection between the endpoint computing device and the wireless network device, to provision an updated wireless credential in the endpoint computing device and the wireless network device, the updated wireless credential being specified by an operator of the first computing site.

Claims (46)

1 . An apparatus comprising:

at least one processing device comprising a processor coupled to a memory;

the at least one processing device being configured to implement a control plane configured for onboarding of an endpoint computing device that is to be deployed at a first computing site:

to obtain a data structure, the obtained data structure comprising information utilizable for generating a temporary wireless credential for the endpoint computing device that is to be deployed at the first computing site, the temporary wireless credential being provisioned in the endpoint computing device at a second computing site different than the first computing site;

to generate, based at least in part on the obtained data structure, the temporary wireless credential for the endpoint computing device;

to provision the temporary wireless credential in a wireless network device at the first computing site;

to verify a wireless connection between the endpoint computing device and the wireless network device at the first computing site, the wireless connection utilizing the temporary wireless credential;

responsive to successfully verifying the wireless connection of the endpoint computing device to the wireless network device at the first computing site utilizing the temporary wireless credential, to provision an updated wireless credential in the endpoint computing device and the wireless network device, the updated wireless credential being specified by an operator of the first computing site;

to receive, from the endpoint computing device, a payload comprising the updated wireless credential signed using a private key of a key pair associated with the endpoint computing device;

to verify the payload received from the endpoint computing device utilizing a public key of the key pair associated with the endpoint computing device; and

responsive to successfully verifying the payload received from the endpoint computing device, to instruct the endpoint computing device to remove the temporary wireless credential provisioned in the endpoint computing device.

2 . The apparatus of claim 1 wherein the first computing site comprises an edge computing site, and the endpoint computing device comprises an edge computing device.

3 . The apparatus of claim 1 wherein the second computing site is operated by a vendor of the endpoint computing device, the vendor of the endpoint computing device being different than the operator of the first computing site.

4 . The apparatus of claim 1 wherein the wireless network device at the first computing site comprises a wireless router.

5 . The apparatus of claim 1 wherein the obtained data structure comprises an ownership voucher associated with the endpoint computing device, the ownership voucher identifying an algorithm for generating the temporary wireless credential for the endpoint computing device.

6 . The apparatus of claim 5 wherein the ownership voucher further identifies the wireless network device at the first computing site.

7 . The apparatus of claim 5 wherein the at least one processing device is further configured to obtain, from an external server operated by a vendor of the endpoint computing device, at least a portion of the algorithm for generating the temporary wireless credential for the endpoint computing device.

8 . The apparatus of claim 1 wherein the control plane is part of a data center external to the first computing site.

9 . The apparatus of claim 1 wherein the obtained data structure comprises an ownership voucher associated with the endpoint computing device, the ownership voucher comprising first key information associated with the control plane, second key information associated with an operator of the first computing site and third key information associated with a vendor of the endpoint computing device.

10 . The apparatus of claim 9 wherein the control plane comprises a first cryptographic certificate associated with the control plane, a second cryptographic certificate associated with the operator of the first computing site, and a third cryptographic certificate associated with the vendor of the endpoint computing device, the control plane being configured to utilize the first, second and third cryptographic certificate to verify the first, second and third key information in the ownership voucher.

11 . The apparatus of claim 10 wherein provisioning the temporary wireless credential in the wireless network device at the first computing site is responsive to a successful verification by the control plane of the first, second and third key information in the ownership voucher.

12 . The apparatus of claim 1 wherein the control plane is configured for communication with the wireless network device at the first computing site via a rendezvous server external to the first computing site and the control plane.

13 . The apparatus of claim 12 wherein the control plane is configured to utilize the rendezvous server for configuring the wireless network device at the first computing site with a device provisioning protocol.

14 . A computer program product comprising a non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processing device implementing a control plane configured for onboarding of an endpoint computing device that is to be deployed at a first computing site causes the at least one processing device:

to obtain a data structure, the obtained data structure comprising information utilizable for generating a temporary wireless credential for the endpoint computing device that is to be deployed at the first computing site, the temporary wireless credential being provisioned in the endpoint computing device at a second computing site different than the first computing site;

to generate, based at least in part on the obtained data structure, the temporary wireless credential for the endpoint computing device;

to provision the temporary wireless credential in a wireless network device at the first computing site;

to verify a wireless connection between the endpoint computing device and the wireless network device at the first computing site, the wireless connection utilizing the temporary wireless credential;

responsive to successfully verifying the wireless connection of the endpoint computing device to the wireless network device at the first computing site utilizing the temporary wireless credential, to provision an updated wireless credential in the endpoint computing device and the wireless network device, the updated wireless credential being specified by an operator of the first computing site;

to receive, from the endpoint computing device, a payload comprising the updated wireless credential signed using a private key of a key pair associated with the endpoint computing device;

to verify the payload received from the endpoint computing device utilizing a public key of the key pair associated with the endpoint computing device; and

responsive to successfully verifying the payload received from the endpoint computing device, to instruct the endpoint computing device to remove the temporary wireless credential provisioned in the endpoint computing device.

15 . The computer program product of claim 14 wherein the obtained data structure comprises an ownership voucher associated with the endpoint computing device, the ownership voucher comprising first key information associated with the control plane, second key information associated with an operator of the first computing site and third key information associated with a vendor of the endpoint computing device.

16 . The computer program product of claim 15 wherein the control plane comprises a first cryptographic certificate associated with the control plane, a second cryptographic certificate associated with the operator of the first computing site, and a third cryptographic certificate associated with the vendor of the endpoint computing device, the control plane being configured to utilize the first, second and third cryptographic certificate to verify the first, second and third key information in the ownership voucher, wherein provisioning the temporary wireless credential in the wireless network device at the first computing site is responsive to a successful verification by the control plane of the first, second and third key information in the ownership voucher.

17 . A method performed by at least one processing device comprising a processor coupled to a memory, the at least one processing device implementing a control plane configured for onboarding of an endpoint computing device that is to be deployed at a first computing site, the method comprising:

obtaining a data structure, the obtained data structure comprising information utilizable for generating a temporary wireless credential for the endpoint computing device that is to be deployed at the first computing site, the temporary wireless credential being provisioned in the endpoint computing device at a second computing site different than the first computing site;

generating, based at least in part on the obtained data structure, the temporary wireless credential for the endpoint computing device;

provisioning the temporary wireless credential in a wireless network device at the first computing site;

verifying a wireless connection between the endpoint computing device and the wireless network device at the first computing site, the wireless connection utilizing the temporary wireless credential;

responsive to successfully verifying the wireless connection of the endpoint computing device to the wireless network device at the first computing site utilizing the temporary wireless credential, provisioning an updated wireless credential in the endpoint computing device and the wireless network device, the updated wireless credential being specified by an operator of the first computing site;

receiving, from the endpoint computing device, a payload comprising the updated wireless credential signed using a private key of a key pair associated with the endpoint computing device;

verifying the payload received from the endpoint computing device utilizing a public key of the key pair associated with the endpoint computing device; and

responsive to successfully verifying the payload received from the endpoint computing device, instructing the endpoint computing device to remove the temporary wireless credential provisioned in the endpoint computing device.

18 . The method of claim 17 wherein the obtained data structure comprises an ownership voucher associated with the endpoint computing device, the ownership voucher comprising first key information associated with the control plane, second key information associated with an operator of the first computing site and third key information associated with a vendor of the endpoint computing device.

19 . The method of claim 18 wherein the control plane comprises a first cryptographic certificate associated with the control plane, a second cryptographic certificate associated with the operator of the first computing site, and a third cryptographic certificate associated with the vendor of the endpoint computing device, the control plane being configured to utilize the first, second and third cryptographic certificate to verify the first, second and third key information in the ownership voucher, wherein provisioning the temporary wireless credential in the wireless network device at the first computing site is responsive to a successful verification by the control plane of the first, second and third key information in the ownership voucher.

20 . The method of claim 17 wherein the control plane is configured for communication with the wireless network device at the first computing site via a rendezvous server external to the first computing site and the control plane.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 9, 2024
From: RAMAIAH, MAHESH BABU; GUPTA, MUKESH; SADHASIVAM, YUVAKRISHNAN
To: DELL PRODUCTS L.P.
Reel/Frame 068846/0237 →
Continuity (1)
Related Publication 20260101182A1 · Apr 9, 2026
References Cited (32)
US 8646060B1 · Ben Ayed · 2014 [cited by examiner]
US 9071967B1 · Davies · 2015 [cited by examiner]
US 11032708B2 · Hsiao · 2021 [cited by examiner]
US 11284258B1 · Wei · 2022 [cited by examiner]
US 11423138B2 · Ferreira · 2022 [cited by examiner]
US 11651357B2 · Kumar · 2023 [cited by examiner]
US 12495283B2 · Jain · 2025 [cited by examiner]
US 12532174B2 · Hsu · 2026 [cited by examiner]
US 12542687B1 · Goodman · 2026 [cited by examiner]
US 20170245146A1 · Rolfe · 2017 [cited by examiner]
US 20170337080A1 · Manescu · 2017 [cited by examiner]
US 20180242129A1 · Shah · 2018 [cited by examiner]
US 20190042779A1 · Agerstam · 2019 [cited by examiner]
US 20190268375A1 · Gundavelli · 2019 [cited by examiner]
US 20190363894A1 · Kumar Ujjwal · 2019 [cited by examiner]
US 20200100108A1 · Everson · 2020 [cited by examiner]
US 20200403994A1 · Bitterfeld · 2020 [cited by examiner]
US 20210014681A1 · Pang · 2021 [cited by examiner]
US 20210075618A1 · Stephenson · 2021 [cited by examiner]
US 20230164139A1 · Chien · 2023 [cited by examiner]
US 20230229758A1 · Terpstra · 2023 [cited by examiner]
US 20230229778A1 · Terpstra · 2023 [cited by examiner]
US 20230229779A1 · Terpstra · 2023 [cited by examiner]
US 20240098492A1 · Hsu · 2024 [cited by examiner]
US 20240291667A1 · Singh · 2024 [cited by examiner]
US 20250373606A1 · Vysyaraju · 2025 [cited by examiner]
Wi-Fi Alliance, “Wi-Fi Easy Connect Specification,” chrome-extension://efaidnbmnnnibpcajpcglclefindmkaj/https://www.wi-fi.org/system/files/Wi-Fi_Easy_Connect_Specification_v3.0.pdf, Version 3.0, Dec. 2022, 188 pages. [cited by applicant]
Fido Alliance, “Client to Authenticator Protocol (CTAP),” https://fidoalliance.org/specs/fido-v2.1-ps-20210615/fido-client-to-authenticator-protocol-v2.1-ps-errata-20220621.html, Jun. 21, 2022, 192 pages. [cited by applicant]
Practical Cryptography for Developers, “Argon2,” https://cryptobook.nakov.com/mac-and-key-derivation/argon2, Accessed Sep. 25, 2024, 5 pages. [cited by applicant]
Practical Cryptography for Developers, “Bcrypt,” https://cryptobook.nakov.com/mac-and-key-derivation/bcrypt, Accessed Sep. 25, 2024, 2 pages. [cited by applicant]
Practical Cryptography for Developers, “Scrypt,” https://cryptobook.nakov.com/mac-and-key-derivation/scrypt, Accessed Sep. 25, 2024, 5 pages. [cited by applicant]
Practical Cryptography for Developers, “PBKDF2,” https://cryptobook.nakov.com/mac-and-key-derivation/pbkdf2, Accessed Sep. 25, 2024, 3 pages. [cited by applicant]